Welcome, Guest. Please login or register.
December 11, 2009, 07:27:39 AM

Login with username, password and session length

341667 Posts
37760 Topics
85728 Members

Latest Member: ealyasss

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Malware POC bypasses CFP Defence Plus
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: Malware POC bypasses CFP Defence Plus  (Read 5821 times)
fOrTy_7
Comodo's Hero
*****
Offline Offline

Posts: 327


« Reply #15 on: August 21, 2008, 09:58:44 AM »

So this atack is based on unauthorized clipboard coping/pasting/etc. AFAIK the development team is aware of that CFP does not 'catch clipboard callbacks' and they're planning to add this feature in future releases.

CFP fails Clipboard Logger Simulation Test
« Last Edit: August 21, 2008, 10:00:23 AM by fOrTy_7 » Logged

Windows XP Pro SP3 32-bit
Comodo Internet Security 3.13.121240.574
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #16 on: August 21, 2008, 01:57:26 PM »

NO, as I understand this attack is different though it,s also related to clipboard.
Logged
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #17 on: August 21, 2008, 03:17:32 PM »

As turns out this PoC is nothing more that a malicious use of legit functions.
If it is an exploit it is one that rely on user interaction.

Poisoning the clipboard can produce a result only if the user doesn't notice that the pasted content is not what he copied.

It is something similiar in concept to Display different text on status bar of hyperlink of all browsers where the user click on a link thinking the alternate text in the statusbar would be the URL he will be redirected to.

It would be about the same thing as forging a link like http://www.google.com/ to point to a totally different site (in this specific case looking at the statusbar prove useful enough).

The clipboard poisoning PoC doesn't work as stated in the zdnet article

This has happened to me twice now, on two separate computers at work. My clipboard has been hijacked with this:

[ malicious URL deleted ]

And once it’s in the clipboard, I can’t copy anything else over it until I’ve restarted the machine.

Maybe the real baddie does something like that but the PoC does not require a reboot. The user need to close only the tab with the PoC page and he will be able to copy anything to the clipboard without having that overwritten again.

To mimic that flash PoC a simple html page with javascript would be enough. Flash is not an indispensable requirement.

Clipboard Protection in this case should not be addressed by CFP. This is a browser based issue.
Even if CFP will handle it many legit sites need that functionality and CFP act at the application level.

If some sort of protection is added to web browser then it would be possible to disable clipboard access on a per site basis.
eg: Opera does this for statusbar javascript access.
« Last Edit: August 21, 2008, 03:23:04 PM by gibran » Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #18 on: August 21, 2008, 04:10:46 PM »

I am not an expert but I have also realized that it can,t be intercepted by a HIPS. It,s a JS problem I think.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #19 on: August 21, 2008, 04:12:48 PM »


eg: Opera does this for statusbar javascript access.
Is there an option in Opera to stop address bar hiding globally?

Thanks
« Last Edit: August 21, 2008, 04:14:40 PM by aigle » Logged
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7655



« Reply #20 on: August 21, 2008, 04:34:42 PM »

Is there an option in Opera to stop address bar hiding globally?
yes
Logged
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #21 on: August 21, 2008, 05:21:52 PM »

Is there an option in Opera to stop address bar hiding globally?

Thanks

A good thing about Opera is that Security related options can be set globally but these setting can be overridden on a per site basis.

cookies, scripts, plugins (which disable flash too), java, referrers can be disabled by default and enabled only on specific sites.
Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #22 on: August 21, 2008, 06:16:27 PM »

I was talking specifically about address bar hiding. Not all JS.
Logged
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #23 on: August 21, 2008, 06:28:14 PM »

I was talking specifically about address bar hiding. Not all JS.

summarizing the answer would be yes it does that and even more Thumb Up
« Last Edit: August 21, 2008, 06:29:58 PM by gibran » Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.054 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com